Privacy and Legal Notice

CIAC INFORMATION BULLETIN

R-012: Vulnerabilities in Microsoft Office

[MS06-062 (922581)]

October 10, 2006 19:00 GMT
[REVISED 19 Oct 2006]

PROBLEM: A remote code execution vulnerability exists in Office.
PLATFORM: Microsoft Access 2000
Microsoft Excel 2000
Microsoft FrontPage 2000
Microsoft Outlook 2000
Microsoft PowerPoint 2000
Microsoft Publisher 2000
Microsoft Word 2000
Microsoft Access 2002
Microsoft Excel 2002
Microsoft FrontPage 2002
Microsoft Outlook 2002
Microsoft PowerPoint 2002
Microsoft Publisher 2002
Microsoft Visio 2002
Microsoft Word 2002
Microsoft Access 2003
Microsoft Excel 2003
Microsoft Excel 2003 Viewer
Microsoft FrontPage 2003
Microsoft InfoPath 2003
Microsoft OneNote 2003
Microsoft Outlook 2003
Microsoft PowerPoint 2003
Microsoft Project 2003
Microsoft Publisher 2003
Microsoft Visio 2003
Microsoft Word 2003
Microsoft Word 2003 Viewer
Storage Management Appliance v2.1 Software running on I, II, III
DAMAGE: If a user were logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system.
SOLUTION: Apply current patches.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/r-012.shtml
  ORIGINAL BULLETIN: Microsoft Security Bulletin MS06-062
   http://www.microsoft.com/technet/security/Bulletin/MS06-062.mspx
  ADDITIONAL LINK: Visit Hewlett-Packard's Subscription Service for:
   HPSBST02161 SSRT061264 rev. 1
  CVE: CVE-2006-3434 CVE-2006-3650 CVE-2006-3864 CVE-2006-3868

REVISION HISTORY:
10/19/2006 - revised o add a link to Hewlett-Packard HPSBST02161 SSRT061264
             rev. 1 for Storage Management Appliance v2.1 Software running on 
			 I, II, III.
			 
			 
			 
[***** Start MS06-062 (922581) *****]



Microsoft Security Bulletin MS06-062

Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (922581)

Published: October 10, 2006

Version: 1.0

Summary

Who Should Read this Document: Customers who use Microsoft Office

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: This bulletin replaces a prior security update. See the frequently asked questions (FAQ) section of this bulletin for the complete list.

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Office 2000 Service Pack 3 - Download the update (KB923274)

Microsoft Access 2000

Microsoft Excel 2000

Microsoft FrontPage 2000

Microsoft Outlook 2000

Microsoft PowerPoint 2000

Microsoft Publisher 2000

Microsoft Word 2000

Microsoft Office XP Service Pack 3 - Download the update (KB923273)

Microsoft Access 2002

Microsoft Excel 2002

Microsoft FrontPage 2002

Microsoft Outlook 2002

Microsoft PowerPoint 2002

Microsoft Publisher 2002

Microsoft Visio 2002

Microsoft Word 2002

Microsoft Office 2003 Service Pack 1 or Service Pack 2 - Download the update (KB923272)

Microsoft Access 2003

Microsoft Excel 2003

Microsoft Excel 2003 Viewer

Microsoft FrontPage 2003

Microsoft InfoPath 2003

Microsoft OneNote 2003

Microsoft Outlook 2003

Microsoft PowerPoint 2003

Microsoft Project 2003

Microsoft Publisher 2003

Microsoft Visio 2003

Microsoft Word 2003

Microsoft Word 2003 Viewer

Microsoft Project 2000 Service Release 1 Download the update (KB923274)

Microsoft Project 2002 Service Pack 1 - Download the update (KB923273)

Microsoft Visio 2002 Service Pack 2 - Download the update (KB923273)

Microsoft Office 2004 for Mac - Download the update (KB924999)

Microsoft Office v. X for Mac - Download the update (KB924998)

Non-Affected Software:

Microsoft PowerPoint 2003 Viewer

Microsoft Works Suites:

Microsoft Works Suite 2004

Microsoft Works Suite 2005

Microsoft Works Suite 2006

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Top of sectionTop of section

General Information

Executive Summary

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

Security Update Information